{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T16:08:03Z","timestamp":1787069283304,"version":"3.56.0"},"reference-count":26,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2017,6,1]],"date-time":"2017-06-01T00:00:00Z","timestamp":1496275200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Systems Journal"],"published-print":{"date-parts":[[2017,6]]},"DOI":"10.1109\/jsyst.2015.2438442","type":"journal-article","created":{"date-parts":[[2015,6,17]],"date-time":"2015-06-17T18:38:15Z","timestamp":1434566295000},"page":"503-512","source":"Crossref","is-referenced-by-count":114,"title":["Automated Insider Threat Detection System Using User and Role-Based Profile Assessment"],"prefix":"10.1109","volume":"11","author":[{"given":"Philip A.","family":"Legg","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Oliver","family":"Buckley","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Goldsmith","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sadie","family":"Creese","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2003.1254322"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(02)00109-8"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1558607.1558670"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74320-0_8"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2008.017224"},{"key":"ref15","first-page":"1","article-title":"SIDD: A framework for detecting sensitive data exfiltration by an insider attack","author":"liu","year":"0","journal-title":"Proc 42nd HICSS"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2013.14"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2012.29"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1080\/19361610.2011.529413"},{"key":"ref19","doi-asserted-by":"crossref","first-page":"217","DOI":"10.1007\/978-3-540-30115-8_22","article-title":"The enron corpus: A new dataset for email classification research","volume":"3201","author":"klimt","year":"2004","journal-title":"Machine Learning ECML 2004"},{"key":"ref4","first-page":"251","article-title":"Insider threat detection by process analysis","author":"bishop","year":"0","journal-title":"Proc IEEE SPW"},{"key":"ref3","first-page":"20","article-title":"Towards a conceptual model and reasoning structure for insider threat detection","volume":"4","author":"legg","year":"2013","journal-title":"J Wireless Mobile Netw Ubiquitous Comput Dependable Appl"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.5038\/1944-0472.4.2.2"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/1595676.1595678"},{"key":"ref8","first-page":"59","article-title":"Invalidating policies using structural information","volume":"5","author":"kammueller","year":"2014","journal-title":"J Wireless Mobile Netw Ubiquitous Comput Dependable Appl"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2014.38"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1002\/0470013192.bsa501"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.camwa.2011.10.038"},{"key":"ref1","author":"cappelli","year":"2012","journal-title":"The CERT Guide to Insider Threats How to Prevent Detect and Respond to Information Technology Crimes"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/2487575.2488213"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2012.6284271"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/PASSAT\/SocialCom.2011.211"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2011.185"},{"key":"ref23","author":"greenberg","year":"1988","journal-title":"Using Unix Collected Traces of 168 Users"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2015.7446229"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1177\/0261927X09351676"}],"container-title":["IEEE Systems Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/4267003\/7959216\/07126970.pdf?arnumber=7126970","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,11]],"date-time":"2021-10-11T02:35:03Z","timestamp":1633919703000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7126970\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,6]]},"references-count":26,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/jsyst.2015.2438442","relation":{},"ISSN":["1932-8184","1937-9234","2373-7816"],"issn-type":[{"value":"1932-8184","type":"print"},{"value":"1937-9234","type":"electronic"},{"value":"2373-7816","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,6]]}}}